Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ansible lxc_container模块安全漏洞
Vulnerability Description
Ansible是美国Ansible公司的一款计算机系统配置管理器,它可用于发布、管理和编排计算机系统。 Ansible 1.9.6-1之前的版本和2.0.2.0之前的2.x版本中的lxc_container模块中的‘create_script’函数存在安全漏洞。本地攻击者可通过向临时目录下的多个文件实施符号链接攻击利用该漏洞写入任意文件或获取权限。(文件包括:/opt/.lxc-attach-script,archive_path/archived container,lxc-attach-script.
CVSS Information
N/A
Vulnerability Type
N/A